Job Closed

This listing is no longer active.

Foxhole Technology, Inc. logo
Foxhole Technology, Inc.

Foxhole Technology provides robust cybersecurity and IT support capabilities for federal civilian and defense agencies. A recognized leader in navigating technology and security challenges, Foxhole delivers mission-focused innovations to answer evolving and complex needs. Our talented employee-owners provide agile, scalable services and solutions that solve operational gaps, operate critical systems, and protect and secure the enterprise – across the organization and around the world.

Assess and Authorize (A&A) Analyst

Security AnalystSecurity AnalystOtherRemoteMid LevelTeam 51-200

Location

United States + 1 moreAll locations: United States | United Arab Emirates

Posted

78 days ago

Salary

0

Seniority

Mid Level

No structured requirement data.

Job Description

Assess and Authorize (A&A) Analyst

Foxhole Technology, Inc.

Role Description The Assess & Authorize (A&A) Analyst supports a DoD customer Cybersecurity Assess & Authorize function to ensure information systems and technologies are assessed and authorized by the Authorizing Official (AO) prior to introduction and operation on the network. This role provides Information System Security Officer (ISSO)-equivalent support by executing the DoD Risk Management Framework (RMF) in accordance with DoDI 8510.01, NIST SP 800-37, and NIST SP 800-30, and by developing and managing authorization packages and continuous monitoring artifacts in eMASS. - Execute RMF activities and provide ISSO / ISSO-equivalent A&A support for assigned systems across the system lifecycle (assessment, authorization, operations, and continuous monitoring). - Support multiple Authorization to Operate (ATO), Authorization to Use (ATU), and Assess Only packages annually (approximately seven (7) authorization packages per year). - Develop, maintain, and submit complete RMF Executive Packages for each authorization, including: - System Security Plan (SSP) - Security Assessment Report (SAR) - Risk Assessment Report (RAR) - Plan(s) of Action and Milestones (POA&M) - Authorization Decision Document - Register systems within the Enterprise Mission Assurance Support Service (eMASS) and use eMASS to support and automate RMF documentation, workflows, and reporting. - Manage and maintain system authorization artifacts in eMASS, ensuring accurate documentation of: - Security controls and implementation status. - Inheritance and shared control relationships. - Risk posture and supporting evidence. - POA&M creation, updates, and tracking. - Authorization status and lifecycle updates. - Coordinate with system owners, ISSMs, assessors, engineers, and AOs to support: - Assessment planning and execution. - Remediation and risk mitigation activities. - Risk acceptance decisions and authorization outcomes. - Ongoing continuous monitoring activities. - Register and maintain all system/application connections in the Systems Network Approval Process (SNAP). - Produce and deliver monthly and annual SNAP registration metrics. - Support cybersecurity compliance, audit readiness, and reporting to ensure systems and technologies remain in an approved security posture. Qualifications - Active Secret security clearance - 3-7 years of relevant cybersecurity / RMF / A&A experience Requirements - Core Tools and Knowledge: - eMASS, DoDI 8510.01, NIST SP 800-37, NIST SP 800-30 - DoD IAM Level III certification (one of the following): CISM, CISSP (or Associate), GSLC, CCISO - Think analytically - Effective verbal and written communication skills - Make decisions - Observe/remember details - Interpret data - Concentrate on tasks - Adjust to change - Handle stress/emotions - Regular attendance - Maintain work schedule - Attend meetings - Meet deadlines - Keyboard/type - Handle confidential information - Use math/calculations - Stay organized - Operate office equipment - May direct others - May be exposed to dust/dirt, humidity, and noise Company Description Foxhole Technology provides robust cybersecurity and IT support capabilities for federal civilian and defense agencies. A recognized leader in navigating technology and security challenges, Foxhole delivers mission-focused innovations to answer evolving and complex needs. Our talented employee-owners provide agile, scalable services and solutions that solve operational gaps, operate critical systems, and protect and secure the enterprise – across the organization and around the world.

Job Requirements

  • Active Secret security clearance
  • 3-7 years of relevant cybersecurity / RMF / A&A experience
  • Core Tools and Knowledge: eMASS, DoDI 8510.01, NIST SP 800-37, NIST SP 800-30
  • DoD IAM Level III certification (one of the following): CISM, CISSP (or Associate), GSLC, CCISO
  • Think analytically
  • Effective verbal and written communication skills
  • Make decisions
  • Observe/remember details
  • Interpret data
  • Concentrate on tasks
  • Adjust to change
  • Handle stress/emotions
  • Regular attendance
  • Maintain work schedule
  • Attend meetings
  • Meet deadlines
  • Keyboard/type
  • Handle confidential information
  • Use math/calculations
  • Stay organized
  • Operate office equipment
  • May direct others
  • May be exposed to dust/dirt, humidity, and noise

Related Job Pages

More Security Analyst Jobs

Quad logo

IT Security Analyst, QuadMed

Quad

QuadMed was founded in 1991 by Harry Quadracci with the belief that there had to be a better way to provide employees with access to affordable, high-quality health care. Now, we partner with employers across the nation to provide value-driven health and wellness services in or near the workplace. Focus on breaking down cost, access, and quality barriers. Empower employees and their families to live healthier, happier lives.

Security Analyst78 days ago
OtherRemoteTeam 10,001

QuadMed is looking for an IT Security Analyst to join our QuadMed IT team. This is a remote role with occasional travel. GENERAL PURPOSE OF JOB The IT Security Analyst assists the Director of Information Security and Compliance in developing, coordinating, and supporting the overall objectives of QuadMed’s information security, risk management and compliance programs. This includes participating in special projects, developing and implementing information security and compliance auditing and monitoring activities, and identifying opportunities to improve QuadMed’s overall risk posture. KEY RESPONSIBILITIES - Conducts reviews of organizational and functional activities, evaluating the adequacy and effectiveness of information technology security controls. (IT General Controls/Splunk/Nessus/3rd Party) - Performs regular audits and participates in a variety of special projects to improve systems or processes and/or to reduce organizational risks. (IT General Controls, SOC2, PCI, HIPAA) - Assists with the development of risk and threat matrices to track organizational risks and mitigation efforts. (Scorecards, Security reporting, System vulnerability tracking) - Coordinates and assists with third party audits and assessments (HIPAA, Risk, DR, PCI, SOC2). - Assists with security risk assessments for new and current third-party vendors. (VSQ, BDS, SOC 2) - Collaborates with other departments to implement process improvement or remediation activities as generated by findings from internal / external audits. - Utilizes reporting tools to identify questionable user behaviors such as inappropriate access, irregular usage patterns, excessive account lock outs or other activities. - Identifies, prepares and maintains appropriate and required data, records, reports and other documentation relevant to carrying out all the above activities and assists with reporting the business’ performance in these areas. - Coordinates employee education, awareness, training and testing activities including phish and insider threat testing. - Actively seeks knowledge of new, automated, or more efficient auditing and monitoring techniques to increase departmental and/or organizational efficiency and effectiveness. - Helps coordinate the reviews of system documentation, and security or compliance related policies and procedures. - Performs other duties as assigned to support departmental initiatives as well as overall strategic goals and objectives of the Company. JOB REQUIREMENTS Education: - Bachelor’s Degree from a four-year college or university in business, healthcare, information technology, security or a related field required Experience: - The ideal candidate will have at least one (1) year experience in a healthcare setting, most notably in a HIPAA, privacy, security or audit/compliance-related role. Certificates, Licenses, Registrations: - Certifications in areas of healthcare compliance, privacy, security, health information management, risk management assurance, internal auditing, and/or Epic Systems preferred Knowledge, Skills & Abilities: - Knowledge of healthcare laws and regulations, auditing and monitoring principles, risk management, electronic health record systems and a strong ability to interpret and present multifaceted concepts and analyses. - Knowledge and experience with HIPAA and other privacy-related regulations and the application of these regulations in a healthcare setting, or a similar job that required interpretation of complex regulations and communication of same to all levels of workforce. - Requires analytical and problem-solving skills to ensure that internal controls, policies and procedures are being followed consistently in order to safeguard the Company’s assets, verify the accuracy and reliability of its data, and promote adherence to the prescribed policies, resulting in recommendations that add value for process improvements throughout all areas of the organization. - Individual must possess excellent attention to detail, strong writing and verbal communications skills, and be able to make critical decisions based on data analysis. - Highly collaborative individual with ability to influence others and build strong professional relationships. - Maintains a high degree of creditability, independence, integrity, confidentiality and trust. - Ability to work independently, make independent judgments and set priorities. - Demonstrated ability to research, compile and analyze regulatory and business information, assess compliance or other business risks, and provide feedback as to resolutions or recommendations for process improvement. - Proven ability to work effectively with diverse populations and a demonstrated commitment to fostering inclusion. - May require occasional travel. Creating a better way. It’s more than just the philosophy we were founded on. It’s our purpose. For our employees, it means more time with patients. Unrushed visits to build meaningful relationships. And most importantly, an opportunity to empower our patients to achieve their full potential – at work and in life. Determined to make a difference? Join our health care revolution and be a part of something better. Harry Quadracci was determined to do things differently, and to do them better. In 1991, the visionary print manufacturing CEO founded QuadMed out of the belief that there had to be a better way to provide his employees with access to affordable, high-quality health care. And what started as doing the right thing, ended up sparking a health care revolution. Now 30 years later, we partner with employers across the nation to provide value-driven health and wellness services in or near the workplace. With a focus on breaking down cost, access and quality barriers, we empower employees and their families to live healthier, happier lives. We offer excellent benefits to eligible employees, including 401(k), holidays, vacations and more. QuadMed and Quad is proud to be an equal opportunity employer. We are committed to creating a place of belonging — a space where employees do not need to sacrifice who they are to exist and grow in our workplace. QuadMed and Quad does not discriminate on any unlawful basis including race, religion, color, national origin, disability, gender, gender identity, sexual orientation, age, marital status, veteran status, genetic information, or any other basis prohibited by applicable federal, state, or local laws. QuadMed and Quad also prohibits harassment of applicants and employees based on any of these protected categories. Drug Free Workplace

United States
Job Closed
Optum logo

Sr Cybersecurity Analyst - Remote or Hybrid in MN and DC

Optum

Optum, part of the UnitedHealth Group family of businesses, is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together. At Optum, we support your well-being with an understanding team, extensive benefits and rewarding opportunities. By joining us, you’ll have the resources to drive system transformation while we help you take care of your future. We recognize the power of connection to drive change, improve efficiency and make a difference in health care. Join a team where your skills and ideas can make an impact and where collaboration is key to creating technology that produces healthier outcomes.

Security Analyst78 days ago
OtherRemoteTeam 160,000Since 2011

Requisition Number: 2344509 Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together. The Enterprise Information Security (EIS) team is responsible for cybersecurity across our organization. We support our business and members by reducing risk, rapidly responding to threats, focusing on business resiliency and securing new acquisitions. UnitedHealth Group's Enterprise Security and Resilience Office (ESRO) is committed to building and maintaining the trust and confidence of our customers and stakeholders. You'll enjoy the flexibility to work remotely * from anywhere within the U.S. as you take on some tough challenges. This position follows a hybrid schedule with four in-office days per week. Primary Responsibilities: - Platform Engineering & Operations (CyberArk / Delinea / Vault) - Engineer, administer, and maintain PAM and secrets management platforms (CyberArk, Delinea, HashiCorp Vault) across development, test, and production environments - Design and implement onboarding patterns for: - Privileged accounts (human and service accounts) - Application secrets (static and dynamic where supported) - Credential rotation / reconciliation workflow - Configure and maintain core PAM capabilities such as: - Vaulting and password rotation policies - Privileged session management / access workflows (where applicable) - Safe / folder / policy structures aligned to least privilege and audibility - Implement and support integrations with enterprise identity and infrastructure services (e.g., directory services, MFA/SSO, PKI/certificates, endpoints, server platforms, cloud, CI/CD) - Develop automation for onboarding and operations using scripting and APIs (e.g., PowerShell, Python, REST), including repeatable configuration and deployment patterns - Partner with application teams to integrate Vault and PAM into SDLC/DevOps pipelines and reduce hard-coded secrets This role participates in a one-week on-call rotation managed in ServiceNow and is responsible for ensuring PAM services are running smoothly with emphasis on service restoration. You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in. Required Qualifications: - Undergraduate degree or 7+ years of equivalent experience - 3+ years in IAM/PAM, security engineering (CyberArk, Delinea, HashiCorp Vault), systems engineering, or infrastructure operations with direct responsibility for Enterprise production platforms Preferred Qualifications: - CyberArk Defender or Sentry (PAM) - Delinea Associate or Engineer - HashiCorp Vault Associate - CompTIA Security - Experience supporting production on-call rotations and major incident response processes Bonus Certifications: - CyberArk Guardian - HashiCorp Vault Operations Professional - CISSP or CISM *All employees working remotely will be required to adhere to UnitedHealth Group's Telecommuter Policy Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you'll find a far-reaching choice of benefits and incentives. The salary for this role will range from $91,700 to $163,700 annually based on full-time employment. We comply with all minimum wage laws as applicable. Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants. At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission. UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations. UnitedHealth Group is a drug-free workplace. Candidates are required to pass a drug test before beginning employment.

Minnesota
$91.7K - $163.7K / year
Job Closed
Optum logo

Senior Cybersecurity Fraud Analyst Remote or Hybrid DC or MN

Optum

Optum, part of the UnitedHealth Group family of businesses, is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together. At Optum, we support your well-being with an understanding team, extensive benefits and rewarding opportunities. By joining us, you’ll have the resources to drive system transformation while we help you take care of your future. We recognize the power of connection to drive change, improve efficiency and make a difference in health care. Join a team where your skills and ideas can make an impact and where collaboration is key to creating technology that produces healthier outcomes.

Security Analyst78 days ago
OtherRemoteTeam 160,000Since 2011

Requisition Number: 2334057 Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together. UnitedHealth Group's Enterprise Security and Resilience Office (ESRO) is committed to building and maintaining the trust and confidence of our customers and stakeholders. The Senior Cybersecurity Fraud Analyst conducts in-depth analyses and correlation of data points to identify, investigate, and remediate risks to businesses and contact centers. This role may provide indirect mentorship to junior analysts and serve as an informal team leader. If you are located in DC or MN, you will have the flexibility to work remotely*, as well as work in the office as you take on some tough challenges. Primary Responsibilities: - Correlate data points across multiple platforms to identify abnormal behavior or fraud - Participate in cross-functional teams to investigate and remediate potential instances of fraud or other cybersecurity issues - Collaborate with enterprise stakeholders to support efficient investigative processes, provide technical expertise as needed, and communicate risks to businesses You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in. Required Qualifications: - Undergraduate degree or equivalent experience - 3+ years of cybersecurity or fraud experience - 1+ years of experience with cyber fraud (e.g. contact center, social engineering, and account takeover fraud) - Experience correlating data points across multiple platforms to identify abnormal behavior or fraud - Proven solid interpersonal and communication skills to collect facts and report findings to internal employees and leaders - Demonstrated ability to identify cyber threats and fraud and remain current on the latest trends and tactics Preferred Qualifications: - Experience investigating health care fraud, waste, and abuse - Relevant cybersecurity certifications such as Security+ or CySA+ - 3+ years of experience with Security Information and Event Management (SIEM) solutions - Experience leveraging solutions (e.g., Pindrop) to identify, investigate, and prevent contact center fraud *All employees working remotely will be required to adhere to UnitedHealth Group's Telecommuter Policy Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you'll find a far-reaching choice of benefits and incentives. The salary for this role will range from $91,700 to $163,700 annually based on full-time employment. We comply with all minimum wage laws as applicable. At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission. UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations. UnitedHealth Group is a drug - free workplace. Candidates are required to pass a drug test before beginning employment.

Minnesota
$91.7K - $163.7K / year
Job Closed
Zoom Video Communications logo

Senior Security Vulnerability Management Engineer

Zoom Video Communications

Zoom Video Communications was founded in 2011 to revolutionize the way teams communicate with its software-based conference room solution. Across all devices an

Security Analyst78 days ago

Immigration sponsorship is not available for this positionWhat you can expect The Security Vulnerability Management Engineer will work closely with Information Security Engineers and cross-functional IT teams to ensure appropriate security controls are in place and that security policies are effectively implemented across the organization. This role is responsible for operating and maturing the vulnerability management program, leading stakeholder engagements, and providing regular updates to leadership on scanning results, risk posture, and remediation efforts. About the Team You will be part of a high-performing, experienced team responsible for maintaining FedRAMP and IL4 compliance for Zoom for Government and Zoom for Defense - our offerings to the U.S. Government. In this role, you will actively scan, monitor, manage, and report on vulnerabilities (CVEs), contribute to monthly POA&M reporting, and analyze and recommend remediation strategies. Your work will directly support maintaining the authorizations required to deliver secure services to U.S. Government customers. Responsibilities - Conducting vulnerability scans across systems, networks, endpoints, and applications. - Validating, prioritizing, and driving remediation of identified vulnerabilities - Partnering with engineering and IT teams to track and improve patching cadence. - Owning vulnerability reporting, including tracking remediation status and risk exposure. - Maintaining and optimize vulnerability scanning tools and schedules. - Integrating vulnerability management tools with SIEM platforms. - Developing dashboards and metrics to provide visibility into security posture for leadership. - Creating and improving tools, documentation, processes, and techniques to support vulnerability remediation. - Leading and coordinating stakeholder meetings to review findings and remediation plans. What we’re looking for - Hold a B.S. or M.S. in Computer Science, Information Security, Engineering or related fields. - Have experience working with CI/CD pipelines, containerized environments, and building, testing, and deployment in an IL4 environment. - Demonstrate understanding of FedRAMP CVE guidelines, remediation timelines, and vulnerability frameworks such as CVE and CVSS. - Bring 5+ years of experience in Information Security, including 4+ years in Vulnerability Management, and 5+ years in DevOps. - Able to perform vulnerability scanning using tools such as Tenable Nessus, Prisma Cloud, Burp Suite, and similar platforms (e.g., Qualys, Tenable). - Demonstrate proficiency in scripting (Python, Bash, PowerShell, or similar) to automate remediation and reporting tasks. - Able to apply experience in Infrastructure Security, including OS hardening, and good knowledge of network technologies and protocols. - Utilize experience in application, network, and system security, including intrusion analysis, malware, antivirus, host-based and network forensics, and tools such as JIRA, Confluence, and ServiceNow. Salary Range or On Target Earnings: Minimum: $124 000,00 Maximum: $271 200,00 In addition to the base salary and/or OTE listed Zoom has a Total Direct Compensation philosophy that takes into consideration; base salary, bonus and equity value. Note: Starting pay will be based on a number of factors and commensurate with qualifications & experience. We also have a location based compensation structure; there may be a different range for candidates in this and other locations At Zoom, we offer a window of at least 5 days for you to apply because we believe in giving you every opportunity. Below is the potential closing date, just in case you want to mark it on your calendar. We look forward to receiving your application! Anticipated Position Close Date: 03/27/26 Ways of Working Our structured hybrid approach is centered around our offices and remote work environments. The work style of each role, Hybrid, Remote, or In-Person is indicated in the job description/posting. Benefits As part of our award-winning workplace culture and commitment to delivering happiness, our benefits program offers a variety of perks, benefits, and options to help employees maintain their physical, mental, emotional, and financial health; support work-life balance; and contribute to their community in meaningful ways. Click Learn for more information. About Us Zoomies help people stay connected so they can get more done together. We set out to build the best collaboration platform for the enterprise, and today help people communicate better with products like Zoom Contact Center, Zoom Phone, Zoom Events, Zoom Apps, Zoom Rooms, and Zoom Webinars. We’re problem-solvers, working at a fast pace to design solutions with our customers and users in mind. Find room to grow with opportunities to stretch your skills and advance your career in a collaborative, growth-focused environment. Our Commitment​ At Zoom, we believe great work happens when people feel supported and empowered. We’re committed to fair hiring practices that ensure every candidate is evaluated based on skills, experience, and potential. If you require an accommodation during the hiring process, let us know—we’re here to support you at every step. If you need assistance navigating the interview process due to a medical disability, please submit an Accommodations Request Form and someone from our team will reach out soon. This form is solely for applicants who require an accommodation due to a qualifying medical disability. Non-accommodation-related requests, such as application follow-ups or technical issues, will not be addressed. #LI-Remote

United States
$124K - $271K / year
Job Closed